Date: 2026-09-10 UTC
Candidate SHA: 9152f5a50de42be55508f0effed5ed09aee44c60
Status: PREPARED_ONLY — NOT PROMOTED TO LIVE PUBLISHER SITE
OpenAI's remote MCP review requires public website, support, privacy, and terms URLs that match the publisher, and the privacy policy must cover user-related data the MCP processes or returns. Fresh external readback shows all four configured URLs return HTTP 200, but /openai-support still serves generic RUMBO IA marketing content and /openai-privacy describes only website/contact processing. Neither is sufficient evidence for the bounded MCP surface.
The live /openai-support page should identify itself as RUMBO IA CRM Support and state, in substance:
REVIEW_REQUIRED and side_effect=false.sebastian@rumbo.verso.fans.The live /openai-privacy page should disclose the actual bounded MCP data flow. A suitable minimum disclosure is:
RUMBO IA CRM provides a bounded MCP integration for OpenAI/ChatGPT. Public v1 does not search or retrieve customer records from a CRM and does not perform CRM mutations or send messages.
When a user asks the plugin to prepare a proposal, the MCP service may process the information the user supplies for that request. Depending on the selected tool, this can include workspace or subject/lead identifiers, note text, stage labels, an optional reason, a communication channel, and an outreach objective. The service returns that supplied information as part of a reviewable proposal or returns bounded service-readiness metadata.
The current public v1 does not intentionally persist those tool inputs to a CRM or application database, does not use them to autonomously contact third parties, and does not sell them. Users should avoid submitting passwords, API keys, access tokens, or personal/customer information that is not necessary for the requested proposal.
Requests are delivered through OpenAI/ChatGPT and the MCP hosting infrastructure. Hosting and network providers may process ordinary technical information such as IP address, browser/client metadata, request timing, and service logs for security and operation according to their own applicable terms and policies.
For privacy requests or questions about RUMBO IA CRM, contact sebastian@rumbo.verso.fans.
Fresh readback of /openai-terms is HTTP 200 and identifies RUMBO IA, but the final publisher review should confirm that the selected verified publisher identity matches the name/contact/website used across the listing and policies.
This document is a handoff artifact only. It does not authorize a production-site change, merge, publication, submission, or policy attestation.
POLICY_SOURCE_PREPARED != LIVE_POLICY_PROMOTED != VERIFIED_PUBLISHER != SUBMISSION_AUTHORITY